IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

App Control: Agents Remain Disconnected After Recent Certificate Expiration and Renewal

App Control: Agents Remain Disconnected After Recent Certificate Expiration and Renewal

Environment

  • App Control Server: 8.9.4 - 8.10.0
  • App Control Agent: All Supported Versions

Symptoms

  • Agent Server Communication Certificate expired, causing all Agents to become disconnected.
  • Communication Certificate was replaced, but Agents remain in a disconnected state.

Cause

By default the Server will prioritize the previous Communication Certificate for 60 minutes after it is replaced. In the event this certificate was expired, this prioritization caused the Agents to remain in a disconnected state.

Resolution

This issue was tracked under EP-19021 and resolved with the release of Server 8.10.2. Previously the workaround involved:
  1. Log in to the Console and navigate to https://ServerAddress/shepherd_config.php
  2. Select the Property CertificateDelaySwapMinutes and change the Value to 0
  3. Restart the App Control Server service.
  4. Verify the Agents are once again showing as Connected.
  5. Return the Property CertificateDelaySwapMinutes to the default Value of 60

Additional Notes

  • The steps are not necessary if the Communication Certificate is/was replaced prior to expiration.
  • This setting is meant as a way to allow time for the Communication Certificate changes to be downloaded by the Agents.

Related Content


Labels (1)
Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎07-10-2023
Views:
701
Contributors